
Search by job, company or skills
Summary
The role of the Thales CDI Business and Product Security GRC Manager is responsible & accountable for Security Governance and Oversight for all Thales CDI Business Security including Operations, Product and Outsourced activities (Manufacturing, Personalization, Software Development, etc.) in APAC. This includes Physical / Logical Security Operations & Certifications compliance to ensure the deployment, implementation and enforcement of security policies and practices are in accordance to Thales CDI and Regulatory Security Requirements.
Responsibilities
Reporting to the CDI Regional Security Director, the role is responsible and accountable for Security Governance and Oversight of CDI Asia Business Security including Operations, Product and Outsourced activities.
Act as the Tactical Process Manager, bridging security personnel and organizational leaders to facilitate achievement of strategic security objectives.
Oversee business and operational security management related to, but not limited to, personnel, physical, production, and IT security across various Secure Product manufacturing and personalization sites within the region (Module, Card, Document & ID).
Ensure information security oversight at Asia regional sites complies with organizational security requirements, certifications, and applicable regulations.
Provide expert advisory and guidance to sites for achieving and maintaining required accreditations and ongoing compliance with security regulations in accordance with regulatory requirements and applicable standards such as GSMA-SAS, ISO 14298, ISO 27001, PCI-CP, etc. (with accountability for outcomes)
Act as Regional (PoC) for Industry 4.0 initiatives for Manufacturing and Banking activities.
Conduct risk assessments and regular audits for internal and external stakeholders
Ensure that security risks and issues are appropriately identified, managed, and mitigated in a measurable manner, following corporate policies and customer requirements.
Experience and familiarity with Cloud Security to ensure GRC and assurance for business cloud security, including AWS, Azure, GCP, Kubernetes, serverless, and data protection practices.
Act as domain expert and trusted advisor to provide management with inputs and recommendations to ensure proactively manage risks and protection of CDI, Customer and partner information, assets and data.
REQUIREMENTS
10 years of progressive experience in IT / IT Security, Security Governance, Risk, and Compliance (GRC), ideally within high-security manufacturing, data center and adjacent industries.
Audit Expertise: 3+ years of experience leading external audits for GSMA-SAS, PCI-CP, or ISO 27001 certifications.
Certifications preferred: CISSP, CISA, CISM.
Operational Physical and IT Security knowledge and experience.
Knowledge in Cyber & Cloud Security
Risk Management: Expertise in conducting formal risk assessments and business impact analyses.
Security auditing experience will be added advantage
GRC tools and security dashboards (e.g., Splunk, Grafana, Kibana, Power BI) to manage and report on security posture.
Able to travel 20-30% of time within Asia as needed.
Other Information:
Working Location: One North
Working Hours: Monday - Friday, 9am - 6pm
Job ID: 144144189